<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://msmvps.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>bits and bytes : Malware</title><link>http://msmvps.com/blogs/susan/archive/tags/Malware/default.aspx</link><description>Tags: Malware</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP2 (Build: 40407.4157)</generator><item><title>Debate with rogue antispyware maker</title><link>http://msmvps.com/blogs/susan/archive/2007/11/04/1282907.aspx</link><pubDate>Sun, 04 Nov 2007 20:55:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1282907</guid><dc:creator>tashi</dc:creator><slash:comments>0</slash:comments><description>I have been following a discussion of iedefender at CastleCops which is five pages long so far. The topic started with: &amp;quot;Attached below is a copy of IEdefender (hxxp://www.iedefender.com/) a new rogue software.&amp;quot; To which the vendor replied:...(&lt;a href="http://msmvps.com/blogs/susan/archive/2007/11/04/1282907.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1282907" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/susan/archive/tags/Security+/default.aspx">Security </category><category domain="http://msmvps.com/blogs/susan/archive/tags/Rogues/default.aspx">Rogues</category><category domain="http://msmvps.com/blogs/susan/archive/tags/Malware/default.aspx">Malware</category></item><item><title>DirectRevenue-Best Offers, shuts down</title><link>http://msmvps.com/blogs/susan/archive/2007/10/25/1264088.aspx</link><pubDate>Thu, 25 Oct 2007 20:25:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1264088</guid><dc:creator>tashi</dc:creator><slash:comments>0</slash:comments><description>Posted on DirectRevenue&amp;#39;s home page and giving no reason for the sudden closure. &amp;quot;Best Offers and Direct Revenue have ceased operations. To service legacy consumers we are maintaining this page of uninstall instructions, an uninstall software...(&lt;a href="http://msmvps.com/blogs/susan/archive/2007/10/25/1264088.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1264088" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/susan/archive/tags/Security+/default.aspx">Security </category><category domain="http://msmvps.com/blogs/susan/archive/tags/Malware/default.aspx">Malware</category><category domain="http://msmvps.com/blogs/susan/archive/tags/Spyware/default.aspx">Spyware</category><category domain="http://msmvps.com/blogs/susan/archive/tags/Adware/default.aspx">Adware</category></item><item><title>VirusRay, latest Zlob rogue anti-spyware program</title><link>http://msmvps.com/blogs/susan/archive/2007/10/23/1260244.aspx</link><pubDate>Tue, 23 Oct 2007 19:53:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1260244</guid><dc:creator>tashi</dc:creator><slash:comments>0</slash:comments><description>The Zlob Trojan Downloader typically poses as audio or video codecs, required to be installed on your computer so you can watch or listen to certain media. VirusRay is just the latest infection that downloads and installs rogue anti-spyware programs and...(&lt;a href="http://msmvps.com/blogs/susan/archive/2007/10/23/1260244.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1260244" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/susan/archive/tags/Security+/default.aspx">Security </category><category domain="http://msmvps.com/blogs/susan/archive/tags/Rogues/default.aspx">Rogues</category><category domain="http://msmvps.com/blogs/susan/archive/tags/Malware/default.aspx">Malware</category><category domain="http://msmvps.com/blogs/susan/archive/tags/Spyware/default.aspx">Spyware</category></item><item><title>Storm Worm Attacks</title><link>http://msmvps.com/blogs/susan/archive/2007/07/09/1012254.aspx</link><pubDate>Mon, 09 Jul 2007 16:06:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1012254</guid><dc:creator>tashi</dc:creator><slash:comments>0</slash:comments><description>The subject matter varies in the attempt to get people to download the bad exe file. Sample: &amp;quot;Virus Activity Detected! Dear Customer, Our robot has detected an abnormal activity from your IP adress on sending e-mails. Probably it is connected with...(&lt;a href="http://msmvps.com/blogs/susan/archive/2007/07/09/1012254.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1012254" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/susan/archive/tags/News+/default.aspx">News </category><category domain="http://msmvps.com/blogs/susan/archive/tags/Spam-Phish/default.aspx">Spam-Phish</category><category domain="http://msmvps.com/blogs/susan/archive/tags/Security+/default.aspx">Security </category><category domain="http://msmvps.com/blogs/susan/archive/tags/Malware/default.aspx">Malware</category></item><item><title>House Passes another Spyware Bill </title><link>http://msmvps.com/blogs/susan/archive/2007/06/07/948693.aspx</link><pubDate>Thu, 07 Jun 2007 17:15:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:948693</guid><dc:creator>tashi</dc:creator><slash:comments>0</slash:comments><description>The House passed a cyber-security bill that would allow for civil penalties of up to $3,000,000. H.R. 964: Securely Protect Yourself Against Cyber Trespass Act or Spy Act. The bill, introduced by Rep. Adolphus Towns (D-New York), to protect users of the...(&lt;a href="http://msmvps.com/blogs/susan/archive/2007/06/07/948693.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=948693" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/susan/archive/tags/News+/default.aspx">News </category><category domain="http://msmvps.com/blogs/susan/archive/tags/Security+/default.aspx">Security </category><category domain="http://msmvps.com/blogs/susan/archive/tags/Malware/default.aspx">Malware</category><category domain="http://msmvps.com/blogs/susan/archive/tags/Spyware/default.aspx">Spyware</category><category domain="http://msmvps.com/blogs/susan/archive/tags/Adware/default.aspx">Adware</category></item><item><title>FTC Closes Spyware Operation</title><link>http://msmvps.com/blogs/susan/archive/2006/09/09/FTC-Closes-Spyware-Operation.aspx</link><pubDate>Sun, 10 Sep 2006 03:05:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:120876</guid><dc:creator>tashi</dc:creator><slash:comments>0</slash:comments><comments>http://msmvps.com/blogs/susan/archive/2006/09/09/FTC-Closes-Spyware-Operation.aspx#comments</comments><description>Enternet Media and ConSpy &amp;amp; Co., an operation that placed &amp;ldquo;Search Miracle&amp;rdquo; &amp;ldquo;Miracle Search&amp;quot; &amp;ldquo;EM Toolbar&amp;quot; &amp;ldquo;EliteBar&amp;rdquo; and &amp;ldquo;Elite Toolbar spyware on consumers&amp;#39; computers; has been ordered by The...(&lt;a href="http://msmvps.com/blogs/susan/archive/2006/09/09/FTC-Closes-Spyware-Operation.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=120876" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/susan/archive/tags/Security+/default.aspx">Security </category><category domain="http://msmvps.com/blogs/susan/archive/tags/Malware/default.aspx">Malware</category><category domain="http://msmvps.com/blogs/susan/archive/tags/Spyware/default.aspx">Spyware</category></item><item><title>The Guardian serves up Zango?</title><link>http://msmvps.com/blogs/susan/archive/2006/08/15/The-Guardian-serves-up-Zango_3F00_.aspx</link><pubDate>Tue, 15 Aug 2006 17:24:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:107727</guid><dc:creator>tashi</dc:creator><slash:comments>0</slash:comments><comments>http://msmvps.com/blogs/susan/archive/2006/08/15/The-Guardian-serves-up-Zango_3F00_.aspx#comments</comments><description>Video nasty, adware nastier say experts of Guardian.co.uk ad By Will Sturgeon Published: Monday 14 August 2006 &amp;quot;In order to view video clips of car smashes and accidents, or download games and screensavers on Zango.com users must install a file called...(&lt;a href="http://msmvps.com/blogs/susan/archive/2006/08/15/The-Guardian-serves-up-Zango_3F00_.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=107727" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/susan/archive/tags/Security+/default.aspx">Security </category><category domain="http://msmvps.com/blogs/susan/archive/tags/Zango/default.aspx">Zango</category><category domain="http://msmvps.com/blogs/susan/archive/tags/Malware/default.aspx">Malware</category><category domain="http://msmvps.com/blogs/susan/archive/tags/Spyware/default.aspx">Spyware</category><category domain="http://msmvps.com/blogs/susan/archive/tags/Adware/default.aspx">Adware</category></item><item><title>bleedingsnort domain alert</title><link>http://msmvps.com/blogs/susan/archive/2006/08/01/bleedingsnort-domain-alert.aspx</link><pubDate>Tue, 01 Aug 2006 20:19:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:106418</guid><dc:creator>Susanh</dc:creator><slash:comments>0</slash:comments><comments>http://msmvps.com/blogs/susan/archive/2006/08/01/bleedingsnort-domain-alert.aspx#comments</comments><description>Bleeding Snort owned the &amp;quot;bleedingsnort.org&amp;quot; domain but unintentionally let it expire, they have released an alert titled &amp;quot; Domain Gone .&amp;quot; http://www.bleedingsnort.com/article.php?story=20060731094455549 Someone else purchased the...(&lt;a href="http://msmvps.com/blogs/susan/archive/2006/08/01/bleedingsnort-domain-alert.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=106418" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/susan/archive/tags/Security+/default.aspx">Security </category><category domain="http://msmvps.com/blogs/susan/archive/tags/Malware/default.aspx">Malware</category></item><item><title>Warner Bros. To Cut Link With Adware Firm Zango</title><link>http://msmvps.com/blogs/susan/archive/2006/07/29/Warner-Bros.-To-Cut-Link-With-Adware-Firm-Zango.aspx</link><pubDate>Sat, 29 Jul 2006 22:10:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:106172</guid><dc:creator>Susanh</dc:creator><slash:comments>0</slash:comments><comments>http://msmvps.com/blogs/susan/archive/2006/07/29/Warner-Bros.-To-Cut-Link-With-Adware-Firm-Zango.aspx#comments</comments><description>&amp;#39;Inappropriate Material&amp;#39; Could Reach Children Special to The Washington Post Friday, July 28, 2006; Page D05 Brian Krebs writes: &amp;quot;Warner Bros. Studios, home to Bugs Bunny, Scooby Doo and Harry Potter, said yesterday that it plans to terminate...(&lt;a href="http://msmvps.com/blogs/susan/archive/2006/07/29/Warner-Bros.-To-Cut-Link-With-Adware-Firm-Zango.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=106172" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/susan/archive/tags/Security+/default.aspx">Security </category><category domain="http://msmvps.com/blogs/susan/archive/tags/Zango/default.aspx">Zango</category><category domain="http://msmvps.com/blogs/susan/archive/tags/Malware/default.aspx">Malware</category><category domain="http://msmvps.com/blogs/susan/archive/tags/Spyware/default.aspx">Spyware</category><category domain="http://msmvps.com/blogs/susan/archive/tags/Adware/default.aspx">Adware</category></item><item><title>Malware evolution: April - June 2006</title><link>http://msmvps.com/blogs/susan/archive/2006/07/25/Malware-evolution_3A00_-April-_2D00_-June-2006.aspx</link><pubDate>Tue, 25 Jul 2006 12:45:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:105674</guid><dc:creator>Susanh</dc:creator><slash:comments>0</slash:comments><comments>http://msmvps.com/blogs/susan/archive/2006/07/25/Malware-evolution_3A00_-April-_2D00_-June-2006.aspx#comments</comments><description>Viruslist.com Jul 21 2006 Alexander Gostev Senior Virus Analyst, Kaspersky Lab, writes: &amp;quot;Superficially at least, the second quarter of 2006 appeared to be one of the most peaceful in recent years. Significant email or network worm epidemics were...(&lt;a href="http://msmvps.com/blogs/susan/archive/2006/07/25/Malware-evolution_3A00_-April-_2D00_-June-2006.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=105674" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/susan/archive/tags/Security+/default.aspx">Security </category><category domain="http://msmvps.com/blogs/susan/archive/tags/Malware/default.aspx">Malware</category></item><item><title>Current state of Spyware </title><link>http://msmvps.com/blogs/susan/archive/2006/07/25/Current-state-of-Spyware-.aspx</link><pubDate>Tue, 25 Jul 2006 04:37:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:105652</guid><dc:creator>Susanh</dc:creator><slash:comments>0</slash:comments><comments>http://msmvps.com/blogs/susan/archive/2006/07/25/Current-state-of-Spyware-.aspx#comments</comments><description>eWEEK Spyware Fades to a Dull Roar, But Targeted Attacks Loom July 20, 2006 Matt Hines writes: &amp;quot;News Analysis: Analysts agree that most enterprises have reached a point where they can effectively block many forms of spyware, but targeted attacks...(&lt;a href="http://msmvps.com/blogs/susan/archive/2006/07/25/Current-state-of-Spyware-.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=105652" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/susan/archive/tags/Security+/default.aspx">Security </category><category domain="http://msmvps.com/blogs/susan/archive/tags/Malware/default.aspx">Malware</category><category domain="http://msmvps.com/blogs/susan/archive/tags/Spyware/default.aspx">Spyware</category></item><item><title>Malware Masquerading as Microsoft Genuine Advantage (WGA) classified as Worm</title><link>http://msmvps.com/blogs/susan/archive/2006/06/30/Malware-Masquerading-as-Microsoft-Genuine-Advantage-_2800_WGA_2900_-classified-as-Worm.aspx</link><pubDate>Fri, 30 Jun 2006 20:51:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:103435</guid><dc:creator>Susanh</dc:creator><slash:comments>0</slash:comments><comments>http://msmvps.com/blogs/susan/archive/2006/06/30/Malware-Masquerading-as-Microsoft-Genuine-Advantage-_2800_WGA_2900_-classified-as-Worm.aspx#comments</comments><description>&lt;p&gt;Security analysts have detected a new piece of malware that appears to run as a Microsoft program used to detect unlicensed versions of its operating system.&amp;nbsp;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;The malware has been classified as a worm and spreads through AOL&amp;#39;s Instant Messenger program, said &lt;a href="http://http://www.sophos.com/pressoffice/contacts/grahamc.html"&gt;Graham Cluley, &lt;/a&gt;senior technology consultant for &lt;a href="http://www.sophos.com/"&gt;Sophos&amp;nbsp;&lt;/a&gt;&amp;nbsp;PLC, a security vendor. &lt;br /&gt;Sophos is calling it &lt;a href="http://http://www.sophos.com/virusinfo/analyses/w32cuebotk.html"&gt;W32/Cuebot-K&lt;/a&gt;&amp;nbsp; a new variation in the Cuebot family of malware. Aliases&amp;nbsp;Backdoor.Win32.IRCBot.st&lt;br /&gt;Win32/IRCBot.OO&lt;br /&gt;&lt;/p&gt;
&lt;p&gt;Cuebot-K can disable other software, shut off the Windows firewall, download new malicious programs, perform basic DDOS (distributed denial of service) attacks, scan local files and spawn a command prompt, Sophos said.&lt;/p&gt;
&lt;p&gt;&lt;br /&gt;Article&amp;nbsp;&lt;a href="http://http://www.pcworld.com/news/article/0,aid,126307,00.asp"&gt;here &lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Information on AIM Viruses/Worms at &lt;a href="http://www.jayloden.com/aimfix.htm"&gt;jayloden.com&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=103435" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/susan/archive/tags/Security+/default.aspx">Security </category><category domain="http://msmvps.com/blogs/susan/archive/tags/Malware/default.aspx">Malware</category></item><item><title>Malware posing as WGA validation and notification</title><link>http://msmvps.com/blogs/susan/archive/2006/06/30/Malware-posing-as-WGA-validation-and-notification.aspx</link><pubDate>Fri, 30 Jun 2006 11:30:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:103313</guid><dc:creator>Susanh</dc:creator><slash:comments>0</slash:comments><comments>http://msmvps.com/blogs/susan/archive/2006/06/30/Malware-posing-as-WGA-validation-and-notification.aspx#comments</comments><description>&lt;p&gt;&lt;font face="Verdana"&gt;New malware recently discovered on at least two help sites.&lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://http://aumha.net/viewtopic.php?p=118674"&gt;AUMHA FORUMS&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;font face="Verdana"&gt;&lt;a href="http://http://www.daniweb.com/techtalkforums/thread48535.html"&gt;DaniWeb&lt;/a&gt;&lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&lt;font face="Verdana"&gt;The file name is wgavn.exe&amp;nbsp;&lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&lt;font face="Verdana"&gt;It creates a service named &amp;quot;Windows Genuine Advantage Validation Notification&amp;quot;, as seen in the HijackThis log. &lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&lt;font face="Verdana"&gt;O23 - Service: Windows Genuine Advantage Validation Notification (wgavn) - Unknown owner - C:\WINDOWS\system32\wgavn.exe&lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&lt;font face="Verdana"&gt;Researchers report the malware disabled various security applications and System Restore.&lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&lt;font face="Verdana"&gt;More &lt;a href="http://blogs.zdnet.com/Spyware/?p=838"&gt;here&lt;/a&gt;&lt;/font&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=103313" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/susan/archive/tags/Security+/default.aspx">Security </category><category domain="http://msmvps.com/blogs/susan/archive/tags/Malware/default.aspx">Malware</category></item></channel></rss>